Here’s Why You Should Never Use AI to Generate Your Passwords

I’m a bit of a broken record when it comes to personal security on the internet: Make strong passwords for each account; never reuse any passwords; and sign up for two-factor authentication whenever possible. With these three steps combined, your general security is pretty much set. But how you make those passwords matters just as much as making each strong and unique. As such, please don’t use an AI program to generate your passwords.

If you’re a fan of chatbots like ChatGPT, Claude, or Gemini, it might seem like a no-brainer to ask the AI to generate passwords for you. You might like how they handle other tasks for you, so it might make sense that something seemingly so high-tech yet accessible could produce secure passwords for your accounts. But LLMs (large language models) are not necessarily good at everything, and creating good passwords just so happens to be among those faults.

AI-generated passwords are not secure

As highlighted by Malwarebytes Labs, researchers recently investigated AI-generated passwords, and evaluated their security. In short? The findings aren’t good. Researchers tested password generation across ChatGPT, Claude, and Gemini, and discovered that the passwords were “highly predictable” and “not truly random.” Claude, in particular, didn’t fare well: Out of 50 prompts, the bot was only able to generate 23 unique passwords. Claude gave the same password as an answer 10 times. The Register reports that researchers found similar flaws with AI systems like GPT-5.2, Gemini 3 Flash, Gemini 3 Pro, and even Nano Banana Pro. (Gemini 3 Pro even warned the passwords shouldn’t be used for “sensitive accounts.”)

The thing is, these results seem good on the surface. They look uncrackable because they’re a mix of numbers, letters, and special characters, and password strength identifiers might say they’re secure. But these generations are inherently flawed, whether that’s because they are repeated results, or come with a recognizable pattern. Researchers evaluated the “entropy” of these passwords, or the measure of unpredictability, with both “character statistics” and “log probabilities.” If that all sounds technical, the important thing to note is that the results showed entropies of 27 bits and 20 bits, respectively. Character statistics tests look for entropy of 98 bits, while log probabilities estimates look for 120 bits. You don’t need to be an expert in password entropy to know that’s a massive gap.

Hackers can use these limitations to their advantage. Bad actors can run the same prompts as researchers (or, presumably, end users) and collect the results into a bank of common passwords. If chatbots repeat passwords in their generations, it stands to reason that many people might be using the same passwords generated by those chatbots—or trying passwords that follow the same pattern. If so, hackers could simply try those passwords during break-in attempts, and if you used an LLM to generate your password, it might match. It’s tough to say what that exact risk is, but to be truly secure, each of your passwords should be totally unique. Potentially using a password that hackers have in a word bank is an unnecessary risk.

It might seem surprising that a chatbot wouldn’t be good at generating random passwords, but it makes sense based on how they work. LLMs are trained to predict the next token, or data point, that should appear in a sequence. In this case, the LLM is trying to choose the characters that make the most sense to appear next, which is the opposite of “random.” If the LLM has passwords in its training data, it may incorporate that into its answer. The password it generates makes sense in its “mind,” because that’s what it’s been trained on. It isn’t programmed to be random.

It’s not hard to make a secure password

Meanwhile, traditional password managers are not LLMs. Instead, they are designed to produce a truly random sequence, by taking cryptographic bits and converting them into characters. These outputs are not based on existing training data and follow no patterns, so the chances that someone else out there has the same password as you (or that hackers have it stored in a word bank) is slim. There are plenty of options out there to use, and most password managers come with secure password generators.

But you don’t even need one of these programs to make a secure password. Just pick two or three “uncommon” words, mix a few of the characters up, and presto: You have a random, unique, and secure password. For example, you could take the words “shall,” “murk,” and “tumble,” and combine them into “sH@_llMurktUmbl_e.” (Don’t use that one, since it’s no longer unique.)

Passkeys may be even more secure than passwords

If you’re looking to boost your personally security even further, consider passkeys whenever possible. Passkeys combine the convenience of passwords with the security of 2FA: With passkeys, your device is your password. You use its built-in authentication to log in (face scan, fingerprint, or PIN), which means there’s no password to actually create. Without the trusted device, hackers won’t be able to break into your account.

Not all accounts support passkeys, which means they aren’t a universal solution right now. You’ll likely need passwords for some of your accounts, which means abiding by proper security methods to keep things in order. But replacing some of your passwords with passkeys can be a step up in both security and convenience—and avoids the security pitfalls of asking ChatGPT to make your passwords for you.

PayPal Warns Of Exposed Social Security Numbers In 6-Month Data Breach

PayPal Warns Of Exposed Social Security Numbers In 6-Month Data Breach
PayPal just disclosed a data breach that exposed sensitive user information, including social security numbers. From July 1st, 2025 to December 12th, 2025, a software glitch in PayPal Working Capital (PPWC) loan applications allowed attackers to gain access to personal user information. While PayPal has since acknowledged and fixed the error,

With NIH in chaos, its controversial director is taking over CDC, too

Jay Bhattacharya, the director of the National Institutes of Health, is now also the acting director of the Centers for Disease Control and Prevention, an unusual arrangement that has drawn swift criticism from researchers and public health experts.

Bhattacharya’s new role comes amid a leadership shakeup in the Department of Health and Human Services under anti-vaccine Health Secretary Robert F. Kennedy Jr. It also marks the third leader for the beleaguered public health agency under Kennedy.

Susan Monarez, a microbiologist and long-time federal health official, held the position of acting director before becoming the first Senate-confirmed CDC director at the end of July. But she was in the role just shy of a month before Kennedy ousted her for—according to Monarez—refusing to rubber-stamp changes to vaccine recommendations made by Kennedy’s hand-picked advisors, who are overwhelmingly anti-vaccine themselves.

Read full article

Comments

Google Highlights Huge AI‑Driven Crackdown On Android Malware And Fraud Apps

Google Highlights Huge AI‑Driven Crackdown On Android Malware And Fraud Apps
Google is flexing its AI muscle in an effort to make its Android ecosystem more safe and secure, as malicious actors are constantly evolving the ways attacks are deployed against victims, including leveraging AI themselves. The company says it was able to use the “investments in AI and real-time defenses over the last year to maintain the

BleachBit 5.1.0 adds cookie manager, CLI negation, expert mode

The BleachBit 5.1.0 release adds a cookie manager to selectively remove cookies in browsers including Google Chrome and Mozilla Firefox. It cleans Chromium when installed as two kinds of Flatpacks, and there are major improvements to cleaners for Opera and LibreOffice. CLI negation makes exception to wildcard arguments. The .deb and .rpm packages are now signed for Debian, Fedora, openSUSE, Ubuntu, Mint.

AMC Theatres Will Refuse To Screen AI Short Film After Online Uproar

An anonymous reader shares a report: When will AI movies start showing up in theaters nationwide? It was supposed to be next month. But when word leaked online that an AI short film contest winner was going to start screening before feature presentations in AMC Theatres, the cinema chain decided not to run the content.

The issue began earlier this week with the inaugural Frame Forward AI Animated Film Festival announcing Igor Alferov’s short film Thanksgiving Day had won the contest. The prize package for included Thanksgiving Day getting a national two-week run in theaters nationwide. When word of this began hitting social media, however, some were dismayed by the prospect of exhibitors embracing AI content, with many singling out AMC Theatres for criticism.

Except the short is not actually programmed by exhibitors, exactly, but by Screenvision Media — a third-party company which manages the 20-minute, advertising-driven pre-show before a theater’s lights go down. Screenvision — which co-organized the festival along with Modern Uprising Studios — provides content to multiple theatrical chains, not just AMC. After The Hollywood Reporter reached out to AMC about the brewing controversy, the company issued this statement to THR on Thursday: “This content is an initiative from Screenvision Media, which manages pre-show advertising for several movie theatre chains in the United States and runs in fewer than 30 percent of AMC’s U.S. locations. AMC was not involved in the creation of the content or the initiative and has informed Screenvision that AMC locations will not participate.”


Read more of this story at Slashdot.

Tunic publisher claims TikTok ran ‘racist, sexist’ AI ads for one of its games without its knowledge

Indie publisher and developer Finji has accused TikTok of using generative AI to alter the ads for its games on the platform without its knowledge or permission. Finji, which published indie darlings like Night in the Woods and Tunic, said it only became aware of the seemingly modified ads after being alerted to them by followers of its official TikTok account.

As reported by IGN, Finji alleges that one ad that went out on the platform was modified so it displayed a “racist, sexualized” representation of a character from one of its games. While it does advertise on TikTok, it told IGN that it has AI “turned all the way off,” but after CEO and co-founder Rebekah Saltsman received screenshots of the ads in question from fans, she approached TikTok to investigate.

A number of Finji ads have appeared on TikTok, some that include montages of the company’s games, and others that are game-specific like this one for Usual June. According to IGN, the offending AI-modified ads (which are still posted as if they’re coming directly from Finji) appeared as slideshows. Some images don’t appear to be that different from the source, but one possibly AI-generated example seen by IGN depicts Usual June’s titular protagonist with “a bikini bottom, impossibly large hips and thighs, and boots that rise up over her knees.” Needless to say (and obvious from the official screenshot used as the lead image for this article), this is not how the character appears in the game.

As for TikTok’s response, IGN printed a number of the platform’s replies to Finji’s complaints, in which it initially said, in part, that it could find no evidence that “AI-generated assets or slideshow formats are being used.” This was despite Finji sending the customer support page a screenshot of the clearly edited image mentioned above. In a subsequent exchange, TikTok appeared to acknowledge the evidence and assured the publisher it was “no longer disputing whether this occurred.” It added that it has escalated the issue internally and was investigating it thoroughly.

TikTok does have a “Smart Creative” option on its ad platform, which essentially uses generative AI to modify user-created ads so that multiple versions are pushed out, with the ones its audience responds more positively to used more often. Another option is the “Automate Creative” features, which use AI to automatically optimize things like music, audio effects and general visual “quality” to “enhance the user’s viewing experience.” Saltsman showed IGN evidence that Finji has both of these options turned off, which was also confirmed by a TikTok agent for the ad in question.

After a number of increasingly frustrated exchanges in which TikTok eventually admitted to Saltsman that the ad “raises significant issues, including the unauthorized use of AI, the sexualization and misrepresentation of your characters, and the resulting commercial and reputational harm to your studio,” the Finji co-founder was offered something of an explanation.

TikTok said that Finji’s campaign used a “catalog ads format” designed to “demonstrate the performance benefits of combining carousel and video assets in Sales campaigns.” It said that this “initiative” helped advertisers “achieve better results with less effort,” but did not address the harmful content directly. Finji seemingly also opted into this ad format without knowing it had done so. TikTok declined to comment on the matter when approached by IGN.

Saltsman was told the issue could not be escalated any higher, with communication not resolved at the time of IGN publishing its report. In a statement to the outlet, Saltsman said she was “a bit shocked by TikTok’s complete lack of appropriate response to the mess they made.” She went on to say that she expected both an apology and clear reassurance of how a similar issue would not reoccur, but was “obviously not holding my breath for any of the above.”

This article originally appeared on Engadget at https://www.engadget.com/gaming/tunic-publisher-claims-tiktok-ran-racist-sexist-ai-ads-for-one-of-its-games-without-its-knowledge-185303395.html?src=rss

How Streaming Became Cable TV’s Unlikely Life Raft

Cable TV providers have spent the past decade losing tens of millions of households to streaming services, but companies like Charter Communications are now slowing that exodus by bundling the very apps that once threatened to replace them.

Charter added 44,000 net video subscribers in the fourth quarter of 2025, its first growth in that count since 2020, after integrating Disney+, Hulu, and ESPN+ directly into Spectrum cable packages — a deal that grew out of a contentious 2023 contract dispute with Disney. Comcast and Optimum still lost subscribers in the quarter, though both saw those losses narrow.

Charter’s Q4 numbers also got a lift from a 15-day Disney channel blackout on YouTube TV during football season, which drove more than 14,000 subscribers to Spectrum. Charter has been discounting aggressively — video revenue fell 10% year over year despite the subscriber gains. Cox Communications launched its first streaming-inclusive cable bundles last month, and Dish Network has yet to integrate streaming apps into its packages at all.


Read more of this story at Slashdot.

Wikipedia blacklists Archive.today, starts removing 695,000 archive links

The English-language edition of Wikipedia is blacklisting Archive.today after the controversial archive site was used to direct a distributed denial of service (DDoS) attack against a blog.

In the course of discussing whether Archive.today should be deprecated because of the DDoS, Wikipedia editors discovered that the archive site altered snapshots of webpages to insert the name of the blogger who was targeted by the DDoS. The alterations were apparently fueled by a grudge against the blogger over a post that described how the Archive.today maintainer hid their identity behind several aliases.

“There is consensus to immediately deprecate archive.today, and, as soon as practicable, add it to the spam blacklist (or create an edit filter that blocks adding new links), and remove all links to it,” stated an update today on Wikipedia’s Archive.today discussion. “There is a strong consensus that Wikipedia should not direct its readers towards a website that hijacks users’ computers to run a DDoS attack (see WP:ELNO#3). Additionally, evidence has been presented that archive.today’s operators have altered the content of archived pages, rendering it unreliable.”

Read full article

Comments

This 27-Inch LG 4K Monitor Just Dropped to Under $200

We may earn a commission from links on this page. Deal pricing and availability subject to change after time of publication.

Gamers and multi-taskers shouldn’t sleep on the 27-inch LG 27UP650K-W Ultrafine 4K monitor—like most options from LG, it’s a versatile and visually striking display with appeal for multimedia, gaming, and office usage. Right now, it’s cheaper than it’s ever been at 30% off, bringing its price down from $279.99 to $196.99.

The monitor offers top-tier 4K clarity for a sub-$200 price tag, with Native 3840×2160 resolution on a 27-inch IPS panel. Its strong color accuracy with HDR400 makes it equally suitable for creative or media consumption. Additionally, it has wide viewing angles and reliable brightness (around 400 nits, which isn’t cinema-quality, but still impressive for a budget 4K monitor), which improves daytime visibility but is modest compared to pricier monitors. Users can adjust the monitor’s pivot, tilt, and height, while HDMI and DisplayPort make it a good choice for most desk setups.

Given its 60Hz refresh rate, it’s better for work, watching movies, and casual gaming; competitive gamers might find it limiting. It also lacks USB-C connectivity, which is a con for those who use laptops like a MacBook. While it can’t offer the same as luxury displays, if you’re looking for a monitor that gets it all done, whether that’s light gaming, office work, media consumption, or content creation, the 27-inch LG 27UP650K-W Ultrafine 4K monitor is a strong budget 4K productivity and casual gaming monitor, particularly at less than $200 with its current discount.

Deals are selected by our commerce team

AMD Zen 6 Olympic Ridge Ryzen CPUs Rumored For A CCD Upgrade With 6 To 24 Cores

AMD Zen 6 Olympic Ridge Ryzen CPUs Rumored For A CCD Upgrade With 6 To 24 Cores
Let’s talk about AMD’s next-generation Zen 6 processors. It has already been all but confirmed that AMD will finally be increasing the core count of a Ryzen CCD to 12 cores from a long time spent at 8. However, a new Xwitter post from well-known hardware enthusiast and occasional leaker HXL seems to have revealed the core counts of the SKUs

PayPal Discloses Data Breach That Exposed User Info For 6 Months

PayPal is notifying customers of a data breach after a software error in a loan application exposed their sensitive personal information, including Social Security numbers, for nearly 6 months last year. From a report: The incident affected the PayPal Working Capital (PPWC) loan app, which provides small businesses with quick access to financing. PayPal discovered the breach on December 12, 2025, and determined that customers’ names, email addresses, phone numbers, business addresses, Social Security numbers, and dates of birth had been exposed since July 1, 2025.

The financial technology company said it has reversed the code change that caused the incident, blocking attackers’ access to the data one day after discovering the breach. “On December 12, 2025, PayPal identified that due to an error in its PayPal Working Capital (‘PPWC’) loan application, the PII of a small number of customers was exposed to unauthorized individuals during the timeframe of July 1, 2025 to December 13, 2025,” PayPal said in breach notification letters sent to affected users. “PayPal has since rolled back the code change responsible for this error, which potentially exposed the PII. We have not delayed this notification as a result of any law enforcement investigation.”


Read more of this story at Slashdot.

OpenAI will reportedly release an AI-powered smart speaker in 2027

OpenAI is reportedly hard at work developing a series of AI-powered devices, including smart glasses, a smart speaker and a smart lamp. According to reporting by The Information, the AI company has a team of over 200 employees dedicated to the project.

The first product scheduled to be released is reported to be a smart speaker that would include a camera, allowing it to better absorb information about its users and surroundings. According to a person familiar with the project, this would extend to identifying objects on a nearby table, as well as conversations being held in the vicinity of the speaker. The camera will also support a facial recognition feature similar to Apple’s Face ID that would enable users to authenticate purchases.

The speaker is expected to retail for between $200 and $300 and ship in early 2027 at the earliest. Reporting indicates the company’s AI-powered smart glasses, a space currently dominated by Meta, would not come until 2028. As for the smart lamp, while prototypes have been made, it’s unclear whether it will actually be brought to market.

Last year OpenAI acquired ex-Apple designer Jony Ive’s startup io Products for $6.5 billion. Ive is considered largely responsible for Apple’s design aesthetic, having been involved in designing just about every major Apple device since joining the company in the ’90s before his departure in 2019. The acquisition of his AI-focused design firm sets the stage for Ive to lead hardware product development now for OpenAI.

Since the partnership was forged, there have already been delays due to technical issues, privacy concerns and logistical issues surrounding the computing power necessary to run a mass-produced AI device. Regardless of the behemoths behind the project, the speaker and other future products may still face a consumer reluctant to buy a product that is always listening to and watching its users.

This article originally appeared on Engadget at https://www.engadget.com/ai/openai-will-reportedly-release-an-ai-powered-smart-speaker-in-2027-173344866.html?src=rss

Google Chrome Now Has Split View (and Two More New Productivity Features)

While I generally consider Chrome to be a mature, feature complete browser, it’s great to see that Google is still making meaningful additions to it. With its latest update, Google Chrome for desktop now has three new productivity features: Split View, PDF annotations, and the ability to save downloads directly to Google Drive. These features are targeted at both regular and enterprise users, the company says, so you don’t need to worry about Workspace exclusivity. Let’s take a look at each new feature and how you can best use it.

Split View lets you boost your productivity

Chrome's Split View feature.

Credit: Google

Over the years, the internet browser has become a super app of sorts, since it has access to so many useful sites and web apps. In Chrome, I often find myself taking notes while attending meetings online, or keeping a second tab open for research while I write articles. For many people, a single Chrome tab or window is no longer enough, and with that in mind, Google’s added Split View to the desktop version of its browser.

Split View merges two tabs and displays them in the same window. You can think of it like the split-screen view in old school video games. You can use Split View by right-clicking any tab and selecting Add Tab to New Split View. For now, Chrome allows you to have a maximum of two tabs side by side in Split View, although I hope you’ll eventually be able to add more in the future. In its current form, the feature is great for using Google Docs while watching an educational video, or similar two-tab use cases. Finally, no more opening single tabs in separate windows and then resizing them into your own, makeshift split view.

You can easily drag the slider in between the two tabs to give one tab more screen space than the other. Or for more control, you can click the Split View button to the left of the address bar and select the Arrange Split View menu (this is also available if you right click the merged tabs in your tab bar). This is an easy way to quickly reverse the order of the two tabs, separate them, or close just one of the tabs.

Annotate PDFs in Chrome

Chrome's PDF annotations feature, shown via a digital signature in a PDF.

Credit: Google

Let’s be honest: Chrome is probably the PDF viewer that most people use. No matter how many fancy PDF editing apps I or my colleagues recommend, for the most part, you’re going to search for and open PDFs in your browser. Luckily, now you no longer have to use a different app for basic annotations. Chrome’s desktop PDF Viewer now has tools for highlighting text, adding notes, and even making digital signatures. You’re still going to need a different app for advanced PDF edits, but Chrome is now capable enough to handle the basics.

Save PDF files directly to Google Drive

Chrome's PDF download to Google Drive feature.

Credit: Google

Whenever you download a PDF file using Google Chrome, it defaults to saving them to the Downloads folder on your computer, or to another location on your hard drive. On desktop, Google now lets you save these files directly to your Google Drive account. This can be very useful if you want to keep your local storage clear. When you open a PDF file in Chrome, you’ll see a Google Drive icon in the toolbar, next to the download button. Clicking the Google Drive icon will automatically save it to the cloud storage service, in a new folder called “Saved from Chrome.”

Why Final Fantasy is now targeting PC as its “lead platform”

For a long time now, PC gamers have been used to the Final Fantasy series treating their platform as somewhat secondary to the game’s core console versions. There are some signs that may be starting to change, though, as director Naoki Hamaguchi has confirmed that the PC is now the “lead platform” for development of the Final Fantasy VII Remake trilogy.

In a recent interview with Automaton, Hamaguchi clarified that the team takes the relatively common practice of creating visual assets for its multiplatform games by targeting “high-end environments first,” then performing a “reduction” for less powerful platforms. These days, that means “our 3D assets are created at the highest quality level based on PC as the foundation,” he said. Players have already noticed this graphical difference in the PC version of Final Fantasy VII Rebirth, Hamaguchi said, and “our philosophy will not change for the third installment.”

While PC gaming is only “gradually expanding in Japan,” Hamaguchi said the rapid growth in international PC gamers has led the company to “develop assets with the broad PC market in mind.”

Read full article

Comments

HSBC To Investors: If India Couldn’t Build an Enterprise Software Challenger, Neither Can AI

India’s IT services giants have spent decades deploying, customizing, and maintaining the world’s largest enterprise software platforms, putting hundreds of thousands of engineers in daily contact with the business logic and proprietary architectures of vendors like SAP and Oracle. None of them have built a competing product that gained meaningful traction against the U.S. incumbents, HSBC said in a note to clients, using this history to argue AI-generated code faces the same structural barriers.

The bank’s analysts contend that enterprise software competition turns on factors that have little to do with the ability to write code — sales teams, cross-licensing agreements, patented IP, first-mover lock-in, brand awareness, and go-to-market infrastructure. If a massive, low-cost, domain-expert workforce couldn’t crack the market over several decades, HSBC argues, the idea that AI-generated code will do so is, in the words of Nvidia’s Jensen Huang that the report approvingly cites, “illogical.”


Read more of this story at Slashdot.

This Is Your Chance to Get a 65-Inch OLED TV for $900

We may earn a commission from links on this page. Deal pricing and availability subject to change after time of publication.

This is one of those rare opportunities that don’t come very often in the consumer tech space: You can get a 2025, 65-inch OLED TV from Samsung for $899.99 (originally $1,999.99) from Best Buy. The catch? It’s the entry-level OLED version, but it’s still an incredible value for the money and the lowest price it has been, according to price-tracking tools. Oh, and the deal expires tonight, Feb. 20, at midnight.

The last time this deal happened was during the Christmas shopping sales, and before that, during Black Friday. So if you’re reading this after the sale ended, you’ll likely see the deal again at some major future sale. If you’ve never owned an OLED before, there are some things you need to know to make sure it’s a good fit for you. Perhaps most important is that you’ll notice they don’t get as bright as QLEDs or LED TVs. Since this is an entry-level OLED, it doesn’t have quantum dot technology, which offers a bit higher brightness. Another missing feature that you should know is that there is no Dolby Vision support. But that is where the cons stop.

The S84F offers the same near-perfect black levels you can expect from OLED TVs, making the contrast look incredible. The pixel-level dimming will also be on par with other high-end OLEDs, as will the wide viewing angles, so multiple people can enjoy the colors. This TV also offers great features for gamers, including 4K gaming at 120Hz across all of its HDMI 2.1 ports, variable refresh rate, and auto low latency mode.

OLED TVs are not normally under a grand, especially newer models like this 2025 one at 65 inches. This is an incredible value for the money for anyone looking to get premium OLED viewing or anyone looking to get their feet wet in the technology.

Deals are selected by our commerce team